Junglewise Threat Intelligence

CVE-2026-96533: Testimonials Widget unauthenticated SSRF via Featured Image URL

CVE-2026-96533 · Severity: info · Published 2026-09-26

Executive brief

The Testimonials Widget WordPress plugin allows unauthenticated attackers to submit arbitrary URLs that the server will fetch and store as publicly accessible files. An attacker can exploit this to make the vulnerable server connect to internal services, read sensitive responses, and potentially access confidential information or services not directly accessible from the internet.

Technical details

The plugin fails to validate user-supplied URLs in the Featured Image field before performing server-side requests and storing responses as public files. This allows unauthenticated attackers to conduct SSRF attacks (CWE-918) by crafting URLs pointing to internal services. An attacker gains the ability to enumerate internal infrastructure, access restricted endpoints, and exfiltrate sensitive data from services bound to localhost or internal networks.

Affected products

  • Testimonials Widget Testimonials Widget through 4.0.4

Timeline

  • 2026-09-24: disclosed
  • 2026-09-26: advisory

References